Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA SY0-701 Exam - Topic 1 Question 56 Discussion

A small business initially plans to open common communications ports (21, 22, 25, 80, 443) on its firewall to allow broad access to its screened subnet. However, their security consultant advises against this action. Which of the following security principles is the consultant addressing?
B) Attack surface
A) Secure access service edge
C) Least privilege
D) Separation of duties

CompTIA SY0-701 Exam - Topic 1 Question 56 Discussion

Actual exam question for CompTIA's SY0-701 exam
Question #: 56
Topic #: 1
[All SY0-701 Questions]

A small business initially plans to open common communications ports (21, 22, 25, 80, 443) on its firewall to allow broad access to its screened subnet. However, their security consultant advises against this action. Which of the following security principles is the consultant addressing?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is Attack surface because opening multiple common service ports unnecessarily increases the number of potential entry points an attacker can target. In the Security+ SY0-701 exam objectives, the attack surface is defined as the total number of exposed interfaces, services, ports, protocols, and access points that an attacker could attempt to exploit. Each open port corresponds to a listening service, and every exposed service represents an opportunity for reconnaissance, exploitation, or abuse.

In this scenario, the business intends to open ports for FTP, SSH, SMTP, HTTP, and HTTPS without clearly limiting access. While some of these services may be required, opening all of them broadly---especially to a screened subnet---significantly expands the attack surface. If any of these services are misconfigured, unpatched, or vulnerable, attackers could exploit them to gain unauthorized access. The SY0-701 study guide emphasizes minimizing exposed services as a foundational defensive strategy, often referred to as reducing attack surface area.

Option C, least privilege, is related but not the best answer. Least privilege focuses on granting users or systems only the minimum access required, whereas this question specifically concerns exposed network services rather than access rights. Option A, secure access service edge (SASE), is a cloud-based architecture model and is unrelated to basic firewall port exposure decisions. Option D, separation of duties, applies to role and responsibility distribution, not network exposure.

By advising against opening multiple common ports, the consultant is recommending a reduction in exposed services to limit opportunities for attack. This aligns directly with SY0-701 guidance on secure network design, firewall hardening, and minimizing externally accessible services.

In summary, limiting open ports reduces the organization's attack surface, making Attack surface the correct and best answer.


Contribute your Thoughts:

0/2000 characters
Tegan
3 days ago
I feel like least privilege also fits. Only open what’s necessary, right?
upvoted 0 times
...
Albert
9 days ago
Definitely! It’s about minimizing vulnerabilities. More ports mean more chances for attacks.
upvoted 0 times
...
Garry
14 days ago
I think the consultant is addressing the attack surface. Too many open ports can be risky.
upvoted 0 times
...
Mabel
19 days ago
Isn't it common to open those ports for business? Sounds normal to me.
upvoted 0 times
...
Frank
24 days ago
Totally agree with the consultant, too many open ports is a bad idea.
upvoted 0 times
...
Rodolfo
29 days ago
Wait, why are they opening so many ports? Seems risky!
upvoted 0 times
...
Linette
1 month ago
I think it's more about least privilege.
upvoted 0 times
...
Karina
1 month ago
Definitely addressing the attack surface here.
upvoted 0 times
...
Leota
1 month ago
I feel like separation of duties could be involved too, but it doesn’t seem to fit as well as the other options. I need to think more about this.
upvoted 0 times
...
Dortha
2 months ago
This question reminds me of a practice scenario we did about firewall configurations. I think the consultant is addressing the attack surface by limiting open ports.
upvoted 0 times
...
Roxane
2 months ago
I’m not entirely sure, but I think the least privilege principle might apply since opening too many ports could give unnecessary access.
upvoted 0 times
...
Tammy
2 months ago
I remember studying the concept of attack surface, which relates to the number of points where an attacker could try to enter a system. This seems relevant here.
upvoted 0 times
...

Save Cancel